<html><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;"><div>DOH!</div><div><br></div><div>Thanks Andrew and Michael and yes, for the record, that correctly activates the filter rule to release the right attributes.</div><div><br></div><div>David Bantz</div><br><div><div>On Tue, 11 Feb 2014, at 11:50 , Andrew Morgan &lt;<a href="mailto:morgan@orst.edu">morgan@orst.edu</a>&gt; wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite">Isn't the entityID the value of Issuer in the SAML request? &nbsp;I think you should use "<a href="https://demo.origamirisk.com/">https://demo.origamirisk.com</a>" instead of "<a href="https://demo.origamirisk.com/Origami/SSO/SamlLogin?providerAccount=UofAK">https://demo.origamirisk.com/Origami/SSO/SamlLogin?providerAccount=UofAK</a>" in your AttributeRequesterString matching rule.<br></blockquote></div><div><br></div><div><br></div><div><div>On Tue, 11 Feb 2014, at 11:51 , Michael A Grady &lt;<a href="mailto:mgrady@unicon.net">mgrady@unicon.net</a>&gt; wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite"><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">The&nbsp;AttributeRequesterString needs to match the EntityID of the requestor, which is in the Issuer element of that Authn Request. It's just "<a href="https://demo.origamirisk.com/">https://demo.origamirisk.com</a>", without the rest of the URL you have in your current&nbsp;AttributeRequesterString values.</div></blockquote></div><div><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;"><br></div></div></body></html>